Skip to content

Senior Security Engineer

Kestra

EuropeRemote

Applying for this one?

We write the CV against this exact posting — its wording, its requirements — not a template with your name in it.

Get my CV for this job

$25, one-time. No subscription.

ABOUT KESTRA

Kestra is the universal orchestration platform: open source, declarative, and designed to orchestrate data pipelines, IT automation, business workflows, and AI/agentic systems.

Trusted by over 10,000 organizations worldwide, including JPMorgan Chase, Bloomberg, FILA, and Crédit Agricole, Kestra orchestrates mission-critical workloads at scale. The open-source project has close to 30,000 GitHub stars, hundreds of contributors, and a fast-growing global community.

ABOUT THE ROLE

Kestra runs arbitrary, user-defined code at scale. Our users write workflows that execute scripts, containers, and queries against their own production systems, through hundreds of community-built plugins, on a platform whose entire source code is public. That is an unusually rich attack surface, and securing it is a genuinely hard engineering problem rather than a checklist exercise. You would be our first dedicated security hire. We're looking for a Senior Security Engineer to own and elevate the end-to-end security posture of our platform, infrastructure, and open-source ecosystem. This is a unique, hybrid role for someone who excels at both sides of security: actively breaking systems to find vulnerabilities (hands-on penetration testing) and actively fixing them (opening PRs, patching infrastructure, and managing supply chain risks). If you want to build a world-class security foundation for a fast-growing open-source and SaaS platform, this role is for you. This is a hands-on engineering role, not a GRC or compliance one.

WHAT YOU WOULD DO

Your first six months would focus on the first three points below. The rest is where the role grows.

- Conduct hands-on penetration testing and threat modeling across our web application, APIs, control plane, and cloud environments.

- Manage end-to-end vulnerability tracking across our codebases, software dependencies (SCA), container images, and cloud infrastructure.

- Proactively fix security flaws by writing patches, submitting Pull Requests (PRs), or collaborating directly with product teams to guide remediation.

- Audit and harden our cloud infrastructure (GCP, Kubernetes clusters, and networking configurations) against external and internal threats.

- Automate security tooling into our CI/CD pipelines (SAST, DAST, dependency scanners) to catch CVEs before code reaches production.

- Perform security code reviews and evaluate third-party dependencies, open-source integrations, and supply-chain risks.

- Lead incident response efforts and establish continuous monitoring, detection, and mitigation strategies.

- Own our public security posture as an open-source project: vulnerability disclosure process, CVE handling, security advisories, and the trust model of our plugin ecosystem.

OUR TECH STACK

- Security & Vulnerability Tools: Trivy, GitHub Security / Dependabot, Elastic Security

- Infrastructure: Docker, Kubernetes, Terraform

- Cloud: GCP

- Programming language: Java, Typescript, Javascript

- Datastore: PostgreSQL, Elasticsearch

- Queuing: Redis, Kafka, AMQP

- Monitoring & Logs: ELK, Prometheus, Grafana

- Deployment & Repository: GitHub Actions, ArgoCD

WHAT WE ARE LOOKING FOR

- 5+ years of experience in Security Engineering, Product Security, DevSecOps, or a combined Offensive/Defensive role.

- Strong hands-on penetration testing background, with proven ability to discover application, API, and network-level vulnerabilities.

- A builder/fixer mindset: You don't just export scanner PDFs; you can read code, understand exploits, write fixes, or provide clear remediation steps to engineers.

- Deep familiarity with cloud security (AWS or GCP) and containerized environments (Kubernetes, Docker).

- Experience with dependency and supply-chain security (CVE management, open-source licensing, SCA tools).

- Fluent in English and comfortable working autonomously in a fully remote environment.

- Adaptability to a fast-paced open-source startup environment where pragmatism and execution speed matter.

PERKS & BENEFITS

- Work from anywhere: We’re a remote-first company, so you can work from wherever feels like home. Plus, you’ll have access to coworking spaces worldwide if you ever need a change of scenery.

- Health coverage: From medical support, dental, and vision, we've got you covered.

- Home office setup on us: We’ll provide all the equipment you need to work comfortably.

OUR HIRING PROCESS

We aim to move quickly (2-3 weeks), but we can adjust the timeline if needed.

- Intro call with the hiring manager (30 min)

- Technical scenario / Practical assessment (2 hours, asynchronous homework focusing on threat assessment and remediation)

- Team chat with one of your future colleagues (30 min)

- Final discussion with one of our co-founders (30 min)

Seen 11 hours ago.

Original posting on Kestra's site ↗

Posting text belongs to the employer. Removal requests: contact us.

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

One job at a time

One posting. One CV. $25.

Pick the job you actually want and we write for it.

Get my CV for this job